Enquire

Legal

Data Policy

AgentLink Pty Ltd (ACN 682 149 211)

This Data Policy forms part of, and is the Data Policy referred to in, the services agreement between the Supplier and the Company to which it is annexed (the agreement). Capitalised terms used but not defined in this Data Policy have the meaning given to them in the agreement. In the event of any inconsistency between this Data Policy and the operative provisions of the agreement, the operative provisions of the agreement prevail to the extent of the inconsistency.

1. Purpose and scope

This Data Policy sets out how the Supplier collects, uses, stores, discloses and otherwise handles data in the course of supplying the Services, and the respective responsibilities of the parties in relation to that data.

This Data Policy applies to all Customer Data (as defined in clause 2) that the Supplier accesses, receives, stores or processes in connection with the Services, whether provided directly by the Company or generated, collected or processed on the Company's behalf.

This Data Policy is to be read together with, and does not limit, the Company's obligations under clause 5 (Data Policy) and clause 8 (Privacy) of the agreement, and the Supplier's Privacy Policy as published at the Supplier's website and updated from time to time.

2. Definitions

In this Data Policy:

Customer Data means all information, records and materials, including any Personal Information, that are provided by or on behalf of the Company to the Supplier, or that are generated, collected, stored or processed by the Supplier on behalf of the Company, in connection with the Services. For the avoidance of doubt, Customer Data does not include the Supplier's Background IP, the Contract IP, or any data or materials proprietary to the Supplier.

Data Breach means unauthorised access to, unauthorised disclosure of, or loss of, Customer Data held by the Supplier, or any other event that compromises the security, confidentiality or integrity of Customer Data.

Sub-processor means any third party engaged by the Supplier to store, host, process or otherwise handle Customer Data in connection with the supply of the Services.

Personal Information has the meaning given in the agreement.

3. Nature of data handled

The Services are intended to involve the handling of business contact information and such other Customer Data as is reasonably necessary to supply the Services.

The Services are not intended or designed to collect, store or process sensitive information, including health, biometric, genetic or financial information, government-issued identifiers, or information about an individual's racial or ethnic origin, political opinions, religious beliefs or sexual orientation.

The Company must not provide, and must not configure or use the Services in a way that causes the Supplier to receive, any sensitive information described in clause 3(b) without the Supplier's prior written agreement. If the Company does so, it does so at its own risk, and the Company indemnifies the Supplier in respect of any liabilities, costs and expenses the Supplier incurs as a result.

4. Responsibilities of the parties

The parties each maintain their own responsibilities in relation to Customer Data as set out below.

Company responsibilities

The Company is responsible for obtaining all consents, and providing all notices, required by Privacy Laws in connection with any Personal Information it provides to, or causes to be processed by, the Supplier, consistent with clause 8.1 of the agreement.

The Company warrants that it is entitled to provide the Customer Data to the Supplier and to authorise the Supplier to handle it as contemplated by the Services and this Data Policy.

The Company must promptly notify the Supplier if any Customer Data changes in a way that affects how it may lawfully be handled, including where an individual's Personal Information must be corrected, updated or deleted.

Where the Company receives a request from an individual to access, correct, or opt out of or withdraw consent to the handling of their Personal Information, and giving effect to that request requires action by the Supplier, the Company must notify the Supplier and the Supplier will comply in accordance with clause 4(h).

Supplier responsibilities

The Supplier will handle Customer Data only for the purpose of supplying the Services, performing its obligations under the agreement, and as otherwise reasonably necessary to operate, maintain, secure, support and improve the Services provided to the Company.

The Supplier does not use Customer Data to train the Supplier's own general-purpose or foundation models. The Supplier may use Customer Data to configure, tune, maintain and improve the custom system built for the Company under the agreement.

The Supplier does not routinely review the contents of Customer Data. The Supplier may access Customer Data where reasonably necessary to provide, maintain, debug, support or secure the Services, to give effect to a request under clause 4(d), or where required by law.

On receiving a valid request or direction notified by the Company under clause 4(d) (including an opt-out, withdrawal of consent, correction or deletion request), the Supplier will comply with that request in respect of Customer Data within its control without undue delay, to the extent it is technically able to do so and consistent with its other legal obligations.

5. Security

The Supplier will take reasonable steps to protect Customer Data from misuse, interference and loss, and from unauthorised access, modification or disclosure, having regard to the nature of the Customer Data and the Services.

Without limiting clause 5(a), the Supplier will maintain encryption of Customer Data in transit and at rest using industry-standard methods.

The Company acknowledges that the Supplier does not currently hold SOC 2 or ISO/IEC 27001 certification, and that no security measures can guarantee absolute security. Subject to the agreement, the Supplier does not warrant that Customer Data will be secure in all circumstances.

The Company is responsible for maintaining the security of its own systems, accounts and credentials used to access or interact with the Services.

6. Sub-processors and third parties

The Company acknowledges and agrees that the Supplier may engage Sub-processors to store, host, process or otherwise handle Customer Data in connection with the supply of the Services. This clause operates together with clause 9 (Subcontracting) of the agreement.

The Supplier maintains a list of its current Sub-processors, which is available at automate.agentlink.au/subprocessors and updated from time to time.

The Supplier will take reasonable steps to ensure that each Sub-processor is bound by obligations in relation to Customer Data that are consistent with this Data Policy. As between the parties, and subject to the agreement, the Supplier remains responsible for the performance of its obligations under this Data Policy.

The Supplier may add, replace or remove Sub-processors from time to time. Where the Supplier does so, it will update the list referred to in clause 6(b).

7. Overseas handling of data

The Company acknowledges and agrees that the Supplier and its Sub-processors may store, host, process or otherwise handle Customer Data outside Australia.

The locations (or the countries or regions) in which Customer Data may be handled are indicated in, or may be identified from, the Sub-processor list available at automate.agentlink.au/subprocessors.

The Company consents to the disclosure and handling of Customer Data, including any Personal Information, outside Australia as contemplated by this clause 7, and acknowledges that this consent is given for the purposes of the Privacy Laws (including Australian Privacy Principle 8). The Company is responsible for ensuring that its own collection notices and consents extend to such overseas handling.

8. Data breach notification

If the Supplier becomes aware of a Data Breach affecting Customer Data, the Supplier will notify the Company without undue delay, and in any event will use reasonable endeavours to do so within 72 hours of becoming aware of the Data Breach.

A notification under clause 8(a) will include, to the extent then known and available to the Supplier, a description of the nature of the Data Breach, the categories of Customer Data affected, the likely consequences, and the measures taken or proposed to address it.

The Supplier will take reasonable steps to investigate, contain and remediate the Data Breach, and will provide the Company with reasonable cooperation and assistance in connection with the Company's own assessment and any mandatory reporting obligations the Company may have.

The parties acknowledge that clause 8.3 of the agreement governs which party will discharge any mandatory reporting obligation. Except where the agreement or a written direction provides otherwise, each party is responsible for its own notification obligations to regulators and affected individuals under the Privacy Laws.

9. Retention, return and destruction

The Supplier will retain Customer Data only for as long as reasonably necessary to supply the Services, to comply with its legal obligations, or as otherwise agreed in writing.

On expiry or termination of the agreement, or on earlier written request, the Supplier will, at the Company's election and to the extent within its control, return or securely destroy Customer Data in its possession, except to the extent that retention is required by law or reasonably necessary for the Supplier to exercise or defend legal rights.

The Supplier may retain Customer Data contained in routine system backups until those backups are overwritten or deleted in the ordinary course, provided that such Customer Data remains subject to the protections of this Data Policy while retained.

This clause 9 operates together with, and does not limit, the Company's obligations under clause 5.2 (Return or Destruction of Data) of the agreement.

10. Liability

Nothing in this Data Policy limits, increases or otherwise varies the exclusions and limitations of liability set out in clause 10 (Liability) of the agreement, which apply to any liability arising under or in connection with this Data Policy.

To the extent permitted by law, and subject to clause 10(a), the Supplier's aggregate liability under or in connection with this Data Policy is limited as set out in clause 10.2 of the agreement.

Nothing in this Data Policy operates to exclude, restrict or modify the application of any consumer guarantee, right or remedy conferred by law that cannot lawfully be excluded, restricted or modified.

11. Updates to this Data Policy

The Supplier may update or amend this Data Policy in accordance with clause 5.3 (Amendment) of the agreement, being on not less than 30 days' prior written notice, provided that any such update or amendment does not materially diminish the Company's rights or impose additional material obligations without the Company's prior written consent.

The current version of the Supplier's Sub-processor list and Privacy Policy, as referred to in this Data Policy, may be updated by the Supplier from time to time without notice, save that changes to Sub-processors are dealt with under clause 6.

End of Schedule 2, Data Policy.